NetMining

Network Intrusion Detection using Active Datamining techniques



ÃÖ±Ù ÀÎÅͳݰú CALS, ÀÎÆ®¶ó³Ý µî°ú °°Àº Á¤º¸ ±â¼úÀÇ È°¿ëÀ¸·Î ÀÎÇØ ¿¹Àü°ú´Â ´Þ¸® °ÅÀÇ ¸ðµç ½Ã½ºÅÛÀÌ °³¹æÈ¯°æ°ú »óÈ£¿¬°á¼º¿¡ ³ëÃâµÇ°Ô µÇ¾ú´Ù. ÀÌ·Î ÀÎÇØ ¾ò°Ô µÇ´Â ÀÌÀ͵µ ¸¹Àº¹Ý¸é ½Ã½ºÅÛ Ä§ÀÔ¿¡ ÀÇÇÑ Á¤º¸ÀÇ À¯Ãâ°ú ÆÄ±«°°Àº ¿ª±â´Éµµ ±âÇϱ޼öÀûÀ¸·Î ´Ã°í ÀÖ´Ù. Áö³­ 2³â°£ÀÇ ÀÚ·á¿¡ ÀÇÇÏ¸é ´õ ÀÌ»ó ¿ì¸®³ª¶óµµ ÄÄÇ»ÅÍ ¹üÁ˷κÎÅÍ ¾ÈÀü Áö´ë°¡ ¾Æ´Ï¸ç ¿ÀÈ÷·Á º¸¾È °ü·Ã ±â¼úÀÇ ³«ÈÄ·Î ÀÎÇÑ ¾öû³­ ÀáÀçÀûÀÎ ¼Õ½ÇÀ» ¿¹»óÇÒ ¼ö ÀÖ´Ù. ÀÌ·¯ÇÑ ÀáÀçÀûÀÎ ¼Õ½ÇÀÇ ¿¹»óÀº ´õ ÀÌ»ó ÇØÅ·¿¡ ÀÇÇÑ ½Ã½ºÅÛ Ä§ÀÔÀÌ ´Ü¼øÇÑ Ãë¹Ì³ª È£±â½É¿¡ ÀÇÇÑ ÇàÀ§°¡ ¾Æ´Ï¶ó´Â µ¥¿¡ ±Ù°ÅÇÑ´Ù. ÁúÀûÀ¸·Î ¾çÀûÀ¸·Î Áõ°¡ÇØ °¡´Â ÀÌ·¯ÇÑ ÄÄÇ»ÅÍ ¹üÁ˸¦ ¸·±â À§ÇÑ ±¹³»ÀÇ ±â¼ú ¼öÁØÀº ¾ÆÁÖ ¹Ì¾àÇÏ´Ù°í º¼ ¼ö ÀÖ´Ù. ƯÈ÷ ½Ã½ºÅÛ ºÒ¹ýħÀÔ¿¡ ´ëÇÑ ½Ç½Ã°£ °æº¸ ü°èÀÇ ±â¼ú °³¹ßÀº Àü¹«ÇÑ »óÅÂÀ̸ç ÀÌ·¯ÇÑ ±â¼úÀº ±â¼úÀû ³­À̵µ°¡ Å©°í °³¹ßºñ¿ëÀÌ ¸·´ëÇÑ ¹Ý¸é ¼ö¿ä°¡ º°·Î ¾ø±â ¶§¹®¿¡ ¹Î°£ »ç¾÷ü¿¡¼­ °³¹ßÀ» ½ÃµµÇϱ⿡´Â ¸¹Àº ¾î·Á¿òÀÌ ÀÖ´Ù. ¶ÇÇÑ ÄÄÇ»ÅÍ º¸¾È¿¡ °ü·ÃµÈ ±â¼úÀº °¢±¹ÀÇ ¼±Áø±â¼úÀ» ¿ÜºÎ¿¡ ÀÌÀü½Ã۱⸦ ²¨·ÁÇÏ´Â °æÇâÀÌ °­Çϱ⠶§¹®¿¡ µ¶ÀÚÀûÀÎ °³¹ßÀÌ ºÒ°¡ÇÇÇÏ´Ù.

  • °ü·Ã µ¥ÀÌÅ͵éÀ» ´Éµ¿ÀûÀ¸·Î ¼öÁýÇÏ¿© µ¥ÀÌÅÍ º£À̽ºÈ­ ÇÒ ¼ö ÀÖ´Â ÀÚµ¿È­µÈ ´É·Â
  • ¹æ´ëÇÑ µ¥ÀÌÅ͵é·ÎºÎÅÍ È¿°úÀûÀ¸·Î ³»ÀçµÈ ±ÔÄ¢À» ã¾Æ³¾ ¼ö ÀÖ´Â ´É·Â
  • »õ·Î¿î »óȲ¿¡ ´ëÇØ ²÷ÀÓ¾øÀÌ Á¤º¸¸¦ °»½ÅÇÒ ¼ö ÀÖ´Â ÀÚµ¿È­µÈ ´É·Â
ÃÖÁ¾¿¬±¸ ¸ñÇ¥ ´Éµ¿ µ¥ÀÌÅÍ ¸¶ÀÌ´× ±â¹ýÀ» ÀÌ¿ëÇÑ Àü»ê¸Á ħÀÔ Å½Áö ½Ã½ºÅÛÀÇ ±¸Ãà
1³âÂ÷ ¿¬±¸ ¸ñÇ¥ Àü»ê¸Á ħÀÔ Å½Áö¸¦ À§ÇÑ ´Éµ¿ µ¥ÀÌÅÍ ¸¶ÀÌ´× ±â¼ú °³¹ß
2³âÂ÷ ¿¬±¸ ¸ñÇ¥ Àü»ê¸Á ħÀÔ Å½Áö ½Ã½ºÅÛ ±¸Çö ¹× Æò°¡


Publications
  • Bayesian Methods for Efficient Genetic Programming, Zhang, B. -T., Genetic Programming and Evolvable Machines, vol. 1, no. 3 , 2000, (to appear).
  • ½Å°æ¸ÁÀ» ÀÌ¿ëÇÑ À¯´Ð½º ½Ã½ºÅÛ »ç¿ëÀÚÀÇ ¸í·É¾î ÆÐÅÏ ºÐ¼®, ±èÀοµ, À庴Ź, µ¥ÀÌÅÍ ¸¶ÀÌ´× ¿¬±¸È¸ pp. 171-178, 1999.
  • Self-Organizing MapÀ» ÀÌ¿ëÇÑ À¯´Ð½º ½Ã½ºÅÛ »ç¿ëÀÚÀÇ ºñÁ¤»ó ÇàÀ§ ŽÁö, ±èÀοµ, À庴Ź, ÀΰøÁö´É, ½Å°æ¸Á ¹× ÆÛÁö ½Ã½ºÅÛ Á¾ÇÕÇмú´ëȸ pp. 221-225, 1999.
  • Genetic programming with active data selection, Zhang, B.T. and Cho, D.Y. Proc. Asia Pacific Conf. on Simulated Evolution and Learning, Canberra, Australia, November 1999.
  • Combining locally trained neural networks by introducing a reject class, Kim, S.-J. and Zhang, B.-T., Proc. Int. Joint Conference on Neural Networks ( IJCNN'99), Washington, D.C., USA, 1999.
  • Active data partioning for building mixture models, Kim, S.J. and Zhang, B.T. Proc. Int. Conf. on Neural Information Processing, October 1998

Project Title ´Éµ¿ µ¥ÀÌÅÍ ¸¶ÀÌ´× ±â¹ýÀ» ÀÌ¿ëÇÑ Àü»ê¸Á ħÀÔ Å½Áö ½Ã½ºÅÛÀÇ ±¸Ãà
Sponsor Korea Research Foundation (KRF). ÇмúÁøÈïÀç´Ü
Duration December 1998 - November 2000
Principal Investogator Prof. Byoung-Tak Zhang
Researcher In Young Kim

Contact In Young Kim
E-Mail iykim@scai.snu.ac.kr
Phone +82-2-880-7302
Fax +82-2-880-7302